Security & data handling

Patterns, not paragraphs.

Systems are read for behavior. Uploads are read for claims. The target can revoke either at any time, and everything is deleted when the case is sealed.

  • Consent before access
  • Read-only scoped OAuth
  • Patterns, not paragraphs
  • Extract-and-discard by default
  • 30-day destruction with certificate

Per-connector data handling

One table. Every connector. No exceptions in the footnotes.

ConnectorZoe readsRetentionRevocationNever stored
QuickBooksFinanceaccounting.readInvoice and ledger metadata, AR aging, close cadence30 days after sealInstant, in QuickBooksLine-item descriptions, customer PII, bank credentials
HubSpotCRMcrm.objects.deals.readDeal-stage transitions, pipeline timestamps, owner changes30 days after sealInstant, in HubSpotEmail bodies, call recordings, contact notes
SalesforceCRMapi refresh_tokenscope pendingAccount concentration, renewal dates, owner history30 days after sealInstant, in SalesforceOpportunity notes, attachments, contact records
GitHubEngineeringrepo:status read:orgscope pendingCommit and PR cadence, review latency, deploy frequency30 days after sealInstant, in GitHubSource code, diffs, commit message bodies
JiraEngineeringread:jira-workCycle time, reopen rate, work-in-progress age30 days after sealInstant, in JiraTicket descriptions, comments, attachments
SlackCommunicationschannels:read users:readChannel graph, response latency, cross-team edges30 days after sealInstant, in SlackMessage bodies, DMs, file contents

Uploaded material

What Zoe reads in full, because you gave it to her to test.

MaterialZoe readsStorageDestruction
Pitch deckClaim LedgerRead in full to extract every claim into the Claim Ledger, one row per claim, then checked against the connected systems.Stored encrypted in the case workspaceDestroyed with the case, under the same certificate
Data-room PDFs and CSVsEvidenceRead to support or refute claims in the ledger. Optional; the deck is the only required upload.Stored encrypted in the case workspaceDestroyed with the case, under the same certificate
Founder Call transcriptScored answersRead to score each answer as answered, dodged, or contradicted against the ledger.Stored encrypted in the case workspaceDestroyed with the case, under the same certificate

Security Scorecard

What we have, and what we don’t yet.

SOC 2

Readiness, not certified

Controls are in place and being evidenced; Type 1 is a future milestone. We won't say certified before it is.

Data residency

US

US-first. We don't claim an EU posture we haven't built.

Destruction

30 days, certificated

Normalized metrics and case data are destroyed 30 days after the case is sealed. You get the certificate, not a promise.

Proof of deletion

Deletion, in writing, to the person who granted it.

Whoever granted the access gets the proof. Thirty days after the investor seals the case, everything it held is destroyed and this document goes to the grantor directly, deal or no deal.

Certificate of destructionIllustrative example
Certificate
ZOE-DC-2025-0814-CEPHEI
Subject
Project Cephei (anonymized)
Granted by
CFO, target company
Sources granted
QuickBooks · HubSpot · GitHub · Slack
Case sealed
14 Aug 2025
Data destroyed
13 Sep 2025, 00:04 UTC
Method
Cryptographic erasure, keys discarded
Digest
sha256:4f9c…a7e1
Verified destroyedIssued automatically

Why it is a document

A retention promise in a paragraph is a marketing claim. A dated artifact with a hash on it is something a security reviewer can file, and something we can be held to.

  • Issued 30 days after the case is sealed, deal or no deal
  • Sent to the grantor, not the requesting fund
  • Covers normalized metrics, the deck, data-room files and the call transcript. Raw metadata was never retained
What the grantor should check →

For the company being read

You’re the one granting access. Here’s exactly what that means.

If an investor has asked you to connect Zoe, you will get a signed link. Open it, read the DPA, and accept it; the acceptance is logged as a consent event. Then connect each system read-only in your own session. The investor never sees a credential. The decision is yours and the scopes are yours to revoke. Message bodies are never stored.

Prepare for diligence →
Your grantsRead-only
  • QuickBooksRevoke
  • HubSpotRevoke
  • SalesforceRevoke
  • GitHubRevoke
  • JiraRevoke
  • SlackRevoke

Each grant is separate. Revoking one doesn’t break the others.

Talk it through

See a Readout Package opened live.

Thirty minutes with a member of our leadership team, and the questions you came with.

Book a Demo